Staff Mission Network Engineer
- True Anomaly
- Denver, Long Beach, United States
- $170,000 – $250,000
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
OUR MISSION
True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
OUR VALUES
- Be the offset. We create asymmetric advantages with creativity and ingenuity.
- What would it take? We challenge assumptions to deliver ambitious results.
- It’s the people. Our team is our competitive advantage and we are better together.
YOUR MISSION
As a Staff Mission Network Engineer, you will be a critical hands-on technical contributor responsible for the deployment, configuration, and operation of terrestrial and cloud network infrastructure supporting classified U.S. Government programs. You will work as part of the Mission Security Engineering team, executing against defined network architectures to deliver secure, compliant, and operational networks across multiple classification levels and locations across the United States.
This is an execution-focused role for a senior network engineer who thrives in the field — someone equally comfortable racking hardware in a classified facility and configuring cloud network infrastructure in AWS. You will work across on-premise and IL-6+ cloud environments, partnering closely with the Staff Security Architect – Networks and cross-functional engineering teams to bring network designs to life and keep them running at mission tempo.
This position requires an active Secret clearance to start, with the ability to obtain and maintain a TS/SCI.
Responsibilities
Deploy, configure, and operate terrestrial network infrastructure for classified capabilities spanning multiple on-premise locations across the U.S., including switching, routing, cabling, and boundary protection hardware
Implement and maintain network configurations in AWS GovCloud and classified cloud environments, including VPCs, transit gateways, route tables, security groups, and network access controls
Configure and maintain network connectivity between AWS classified cloud environments, USG networks, and end-user physical networks in close coordination with cloud engineers
Implement endpoint networks connecting on-premise and IL-6+ cloud environments across geographically distributed sites
Deploy and configure network hardware in accordance with DoD Approved Products Lists (APLs) and Trade Agreements Act (TAA) compliance requirements
Implement and validate network security controls including boundary protection, traffic segmentation, filtering, and encrypted communications across classification domains
Implement and validate DISA STIG requirements at the network and infrastructure layer across on-premise and cloud environments
Identify and remediate network-layer findings from STIGs, vulnerability scans, and SCA activities to maintain ATO posture
Support RMF activities including network control implementation, STIG validation, and assessment preparation in coordination with ISSEs
Maintain accurate and up-to-date network documentation including topology diagrams, as-built configurations, and security artifacts required for ATO activities
Partner with ISSEs, industrial security personnel, cloud engineers, and the Staff Security Architect – Networks to ensure network deployments meet program security and compliance requirements
Deploy, configure, and operate NSA Type 1 cryptographic devices (including KG-175 TACLANE and KG-142 units) within terrestrial classified networks, ensuring proper integration with network infrastructure and compliance with NSA/CSS operational policies
Manage keying material (KEYMAT) handling, DTA transfers, and controlled cryptographic item (CCI) documentation in accordance with USG regulations and best practices
Troubleshoot and resolve NSA Type 1 device connectivity, configuration, and interoperability issues across classified terrestrial network environments
Troubleshoot and resolve network connectivity, configuration, and performance issues across classified on-premise and cloud environments
Required Qualifications
10+ years of hands-on experience in network engineering, with demonstrated experience deploying and operating classified DoD or IC networks at classification levels up to and including TS/SCI and special access networks
Active Secret clearance required; must be able to obtain and maintain TS/SCI
DoD 8140 IAT Level III certification (CASP+, CISSP, CISA, or equivalent) required
Deep expertise in IP networking including routing protocols, switching, VLANs, subnetting, QoS, and network boundary protection
Experience deploying and configuring network hardware in compliance with DoD APL and TAA requirements
Working knowledge of NIST SP 800-53 and how network controls are implemented, documented, and validated within the RMF process
Hands-on experience implementing STIGs at the network and infrastructure layer
Experience supporting RMF and ATO activities including control implementation and assessment preparation
Strong documentation skills, with experience producing network diagrams, as-built documentation, and hardware configuration records
Ability to collaborate effectively with ISSEs, architects, cloud engineers, and cross-functional program teams
Bachelor's degree in Computer Science, Cybersecurity, Engineering, Information Technology, or related field (or equivalent experience)
Preferred Qualifications
Active Top Secret or TS/SCI clearance
Professional networking certifications (e.g., CCNP, CCIE, or equivalent)
Experience with AWS IL-6+ or Microsoft Azure IL-6+ classified cloud environments, including VPC/VNet design, transit gateway configuration, and network security controls
Experience supporting classified ground station or satellite Command & Control (C2) network infrastructure is a significant plus
Hands-on experience deploying, configuring, and operating NSA Type 1 cryptographic devices, including KG-175 (TACLANE) and/or KG-142 units, within terrestrial classified network environments
Familiarity with KEYMAT handling procedures, DTA transfer processes, and CCI inventory and documentation requirements
Experience with Cross Domain Solutions (CDS), data guards, or inter-domain network traffic control
Experience with NSA Type 1 cryptographic devices and their integration into classified network architectures
Familiarity with zero trust network architectures applied to classified or highly regulated environments
Experience supporting DoD or IC customers through ATO, re-ATO, or continuous authorization
Familiarity with Software Defined Networking (SDN) or network automation tooling
Work Environment
Fast-paced, mission-critical environment supporting national security space operations
Requires coordination across distributed teams including spacecraft engineers, ground operations, and government partners
High degree of autonomy and ownership as a trusted, cleared team member
Occasional travel to government sites, classified facilities, launch facilities, or partner locations may be required
What We Offer
Competitive salary commensurate with experience and clearance level
Opportunity to drive security posture for cutting-edge space systems with national security impact
Professional development support including conferences, training, and security certifications
Collaborative culture working alongside spacecraft engineers, mission operators, and experienced security professionals
Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave
COMPENSATION
- Base Salary: Denver - $170,000 - $250,000, Long Beach - $180,000 - $260,000
- Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave
Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, location, and experience.
ADDITIONAL REQUIREMENTS
- Work Location— Long Beach, CA, or Denver, CO. While we observe a hybrid work environment, you will need to be onsite as the business needs require. Onsite requirements are subject to change, particularly when work on classified systems is required. On an average week, you can expect to spend at least 3 days per week in office.
- Work environment—the work environment; temperature, noise level, inside or outside, or other factors that will affect the person's working conditions while performing the job.
- Physical demands—the physical demands of the job, including bending, sitting, lifting and driving.
This position will be open until it is successfully filled. To submit your application, please follow the directions below. #LI-Onsite
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.
Skills
- Network Engineering
- AWS Cloud Networking
- Cisco Routing and Switching
- Firewall configuration
- Classified Network Operations
- Network Security
- Troubleshooting









